7.5
CVSSv2

CVE-2013-5350

Published: 24/01/2014 Updated: 24/01/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 prior to 3.6.13.1 and 3.8.9 prior to 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote malicious users to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.

Vulnerable Product Search on Vulmon Subscribe to Product

tejimaya openpne 3.6.13

tejimaya openpne 3.8.9